Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 4 Sep 2006 14:43:24 -0400
From:      Kris Kennaway <kris@obsecurity.org>
To:        Andrew Pantyukhin <infofarmer@FreeBSD.org>
Cc:        FreeBSD Ports <ports@freebsd.org>, Kris Kennaway <kris@obsecurity.org>
Subject:   Re: World-writable files installed by ports
Message-ID:  <20060904184324.GA41301@xor.obsecurity.org>
In-Reply-To: <cb5206420609041125i28006394ofa49371e0fcef05@mail.gmail.com>
References:  <cb5206420608310715y7f9718e2j8736237f7943fad@mail.gmail.com> <20060831141924.GA30325@xor.obsecurity.org> <20060901012715.GA64266@xor.obsecurity.org> <cb5206420609010130j60f0b4a9i5401ab9fe6af2e7e@mail.gmail.com> <cb5206420609040948u7643f404ibb88bbd43d58f47d@mail.gmail.com> <20060904165520.GA39206@xor.obsecurity.org> <cb5206420609041035x14821e1csf22269db7147c37b@mail.gmail.com> <20060904175555.GA40371@xor.obsecurity.org> <cb5206420609041125i28006394ofa49371e0fcef05@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--x+6KMIRAuhnl3hBn
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Sep 04, 2006 at 10:25:09PM +0400, Andrew Pantyukhin wrote:

> >> BTW, I wonder why www/phpmyfaq is not in your list.
> >
> >What a+w file does it install?
>=20
> sat@sat64:~> find /usr/local/www/phpmyfaq -perm -a+w
> /usr/local/www/phpmyfaq/inc
> /usr/local/www/phpmyfaq/images
> /usr/local/www/phpmyfaq/attachments
> /usr/local/www/phpmyfaq/data
> /usr/local/www/phpmyfaq/pdf
> /usr/local/www/phpmyfaq/xml
>=20
> sat@sat64:~> find /usr/local/www/phpmyfaq -perm -a+w | xargs ls -ld
> drwxrwxrwx  2 www  www   512 Sep  4 22:19=20
> /usr/local/www/phpmyfaq/attachments
> drwxrwxrwx  2 www  www   512 Sep  4 22:19 /usr/local/www/phpmyfaq/data
> drwxrwxrwx  2 www  www   512 Sep  4 22:19 /usr/local/www/phpmyfaq/images
> drwxrwxrwx  2 www  www  1024 Sep  4 22:19 /usr/local/www/phpmyfaq/inc
> drwxrwxrwx  2 www  www   512 Sep  4 22:19 /usr/local/www/phpmyfaq/pdf
> drwxrwxrwx  2 www  www   512 Sep  4 22:19 /usr/local/www/phpmyfaq/xml

Hmm, I wonder if the security-check target is broken with plist
substitutions.

Kris


--x+6KMIRAuhnl3hBn
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (FreeBSD)

iD8DBQFE/HPMWry0BWjoQKURAijPAKC0HZmIZkyolH4b0UDmawuf6AC8rQCg6KCQ
7baQ4JpZGLr4E4L2lg8CDy0=
=7cPT
-----END PGP SIGNATURE-----

--x+6KMIRAuhnl3hBn--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060904184324.GA41301>